Steps and facts
- Use the correct workspace for each organization. Its published knowledge, conversations, CRM connection and billing remain scoped to that company.
- Only authorized owners/admins should change integrations or sensitive workspace settings. Teammates should receive the access needed for their work.
- Keep provider credentials in the supported private configuration. Never upload them as knowledge or share them in a public demo.
- Use HTTPS and inspect permitted domains, activity and failures. If a credential is exposed, have the responsible administrator rotate it.
- Public website knowledge must not reveal internal notes or another customer's information. CRM answers require the current customer's fresh permitted facts.
- Do not give the AI an unverified payment, delivery or booking status. Use a supported source and escalate when the required facts are unavailable.